Yes, but on one condition: that the file's data never leaves an environment that guarantees its confidentiality. The lawyer's professional secrecy (secret professionnel) is general and absolute (article 66-5 of the Law of 31 December 1971). Entrusting a document to an AI does not lift this obligation: it is the lawyer who remains responsible for the third party to whom they pass on their client's information. A legal AI is therefore only compatible with professional secrecy if it rests on compliant, sovereign hosting, adapted to health data where personal injury is involved.
The lawyer's professional secrecy is laid down by article 66-5 of the Law of 31 December 1971 and by the profession's national code of conduct (Règlement intérieur national). In advisory work as in litigation, it covers consultations, correspondence between the lawyer and their client, meeting notes and all the documents in the file.
This secrecy is a matter of public policy: case law and professional ethics describe it as general, absolute and unlimited in time. The lawyer can neither share it nor delegate it freely. When they use a service provider, they must make sure that the provider offers equivalent guarantees of confidentiality, on pain of engaging their own liability.
Using a generative AI means, technically, transmitting data to it: the facts of the file, documents, sometimes identity or health details. This data then passes through the provider's servers, is processed there, sometimes stored, and may, depending on the tool, be used to train the models.
This is where the risk lies. A consumer AI, whose servers are located outside the European Union and whose terms of use allow the reuse of the data entered, does not offer the guarantees that professional secrecy requires. The problem is not the reliability of the answers, which we deal with in our article on the risk of hallucination, but the confidentiality of what is transmitted. The two issues are distinct and add up.
In personal injury, the question becomes more sensitive still. A compensation file contains health data: medical expert reports, certificates, operative notes. This data falls under a specific protective regime.
The hosting of personal health data is governed by article L1111-8 of the Public Health Code, which provides for a dedicated certification known as "HDS" (hébergeur de données de santé, health-data hosting). The Conseil national des barreaux (France's national bar council) recommends using HDS-certified providers for the exchange and storage of documents covered by professional secrecy. An AI handling medical documents should therefore rely on a certified infrastructure, which most generalist tools are not.
Beyond professional secrecy, any processing of personal data falls under the General Data Protection Regulation (GDPR). The lawyer, as data controller, must be able to account for the legal basis of the processing, its purpose, its retention period and the place of hosting.
Sovereignty adds a dimension: hosting the data in France, on an infrastructure not subject to extraterritorial legislation, reduces exposure to access by foreign authorities. For a law firm, this is a selection criterion as much as an argument of trust towards its clients. A sovereign environment is not a marketing extra, it is what makes it possible to align the tool with the profession's obligations.
Before adopting an AI, a few questions make it possible to sort quickly:
| Question | Why it matters |
|---|---|
| Where is the data hosted? | The location determines the applicable law and exposure to foreign statutes |
| Is the hosting HDS-certified? | Essential as soon as a file contains health data |
| Is my data used to train the models? | Uncontrolled reuse is incompatible with professional secrecy |
| Who, at the provider, can access the data? | Secrecy requires guarantees of restricted and logged access |
| Can I trace each answer back to its source? | Traceability drives verifiability and the lawyer's liability |
These questions apply whatever the tool considered, and overlap with the criteria we detail in our overview of the best legal AI for lawyers.
Plato is designed for this use: a sovereign environment hosted in France, adapted to the sensitive data of personal injury, with full traceability where each figure and each reference trace back to their source. The aim is not to relieve the lawyer of their secrecy, but to give them a tool that respects it by design, so that they can delegate the valuation without delegating their responsibility. The final control stays theirs.
Can an AI respect the lawyer's professional secrecy?
Yes, provided the file's data stays in a confidential environment: compliant hosting, no reuse of the data to train the models, restricted and logged access. It is the lawyer who remains responsible for the provider they choose.
Which text underpins the lawyer's professional secrecy?
Article 66-5 of the Law of 31 December 1971, supplemented by the profession's national code of conduct (Règlement intérieur national). Secrecy covers consultations, correspondence, notes and file documents; it is general, absolute and unlimited in time.
What is HDS certification and when is it required?
The "health-data hosting" certification (hébergeur de données de santé) is governed by article L1111-8 of the Public Health Code. It concerns the hosting of personal health data. In personal injury, where files contain medical documents, the Conseil national des barreaux recommends using an HDS-certified host.
Can you use ChatGPT for a confidential file?
It is inadvisable for data covered by secrecy: consumer tools often host data outside the European Union and may reuse it. The confidentiality risk adds to the hallucination risk, which is a separate matter.
What does sovereign hosting bring?
Hosting the data in France, on an infrastructure not subject to extraterritorial legislation, reduces exposure to access by foreign authorities and eases GDPR compliance. It is a selection criterion for a firm and a mark of trust for its clients.
Which questions should you ask a legal AI provider?
Where the data is hosted, whether the hosting is HDS-certified, whether the data is used to train the models, who can access it, and whether you can trace each answer back to its source. These five questions are enough to rule out most non-compliant tools.
Does the AI relieve the lawyer of their liability?
No. The lawyer remains responsible for secrecy and for checking the work produced. A tool like Plato is designed to respect secrecy by design and to make each result traceable, but the final verification and decision remain the lawyer's.